# WordPress Integration

The official FindIP Shield plugin on WordPress.org adds visitor risk
intelligence to any WordPress site — VPN, proxy, Tor, relay, hosting,
datacenter, malicious-IP, and network-service flags plus a risk score per
session — without reading form values, passwords, or payment fields.

## Install

1. In WordPress admin, open **Plugins → Add New Plugin**, search for
   **FindIP Shield**, install and activate.
2. In the FindIP dashboard, create a Shield site whose domain matches your
   WordPress hostname.
3. Open **Settings → FindIP Shield**, paste the public site key (`pub_…`),
   and save.
4. Load a public page and confirm the first event on your site's Install
   page in the FindIP dashboard.

The plugin pins an exact, immutable Shield SDK build from
`cdn.findip.net` with subresource integrity — the browser refuses to run a
script that does not match the recorded hash. Login pages are covered as
well as public pages.

## Settings

- **Privacy mode**: strict (default), balanced, advanced — identical to the
  Shield SDK modes. Strict collects only user agent, language, and timezone
  and sets no visitor cookie.
- **Automatic tracking**: page views, one `session_start` per browser
  session, and form-activity events derived from form *attributes* only —
  field values are never read.
- **Consent**: with **require consent** enabled, the plugin starts in the
  configured pre-consent behavior (`strict` or `disabled`) until your
  consent tool dispatches a `findip:consent` event:

```js
document.dispatchEvent(new CustomEvent('findip:consent', {
  detail: { granted: true }
}));
```

## WooCommerce

If WooCommerce is active, the plugin can additionally emit cart, checkout,
payment-failure, and order-completion context (toggleable). For richer
storefront signals with per-event controls, use the dedicated
**FindIP Shield for WooCommerce** plugin instead — the two plugins are
mutually exclusive and must not run together.

## Attribution

Events report `integration: wordpress` in the dashboard, so WordPress
traffic is distinguishable from plain JavaScript or Google Tag Manager
installations.

## Server-side verification

Browser risk responses are informational. For decisions that matter
(sign-ups, checkouts), verify the session server-side with your secret key —
see the Server Verification page.

---

Canonical page: https://www.findip.net/docs/shield/wordpress · Markdown: https://www.findip.net/docs/shield/wordpress.md · All Shield docs in one file: https://www.findip.net/llms-full.txt
